Vulnerabilidades em GNU

106 resultados
Análise Vexday

O ecossistema GNU apresenta 88 CVEs catalogadas, com uma taxa de exploração ativa 2,5 vezes acima da média geral do catálogo CISA KEV — sinal de que, apesar do volume relativamente contido, as vulnerabilidades que surgem tendem a atrair atenção de agentes maliciosos de forma desproporcional. O ponto de maior atenção imediata é CVE-2026-24061, atualmente em exploração ativa e com EPSS de 0,9887, indicando probabilidade extremamente elevada de exploração observada ou iminente. A falha mais recorrente é CWE-119 (escrita/leitura fora dos limites de buffer), padrão que historicamente facilita execução de código arbitrário e elevação de privilégios. Com 10 CVEs acompanhadas de PoC pública e 13 surgidas nos últimos 90 dias, equipes de segurança devem monitorar ativamente o pipeline de patches e priorizar a mitigação das falhas críticas e exploráveis antes de avançar para o restante do portfólio.

CVE-2025-1152LOWGNU Binutils ld xstrdup.c xstrdup memory leakEPSS 0.6%CVE-2025-1150LOWGNU Binutils ld libbfd.c bfd_malloc memory leakEPSS 0.6%CVE-2025-1151LOWGNU Binutils ld xmemdup.c xmemdup memory leakEPSS 0.6%CVE-2025-1182LOWGNU Binutils ld elflink.c bfd_elf_reloc_symbol_deleted_p memory corruptionEPSS 0.6%CVE-2014-3591Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximEPSS 0.6%CVE-2025-1149LOWGNU Binutils ld xmalloc.c xstrdup memory leakEPSS 0.6%CVE-2025-43920MEDIUMGNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to executeEPSS 0.6%CVE-2025-1179LOWGNU Binutils ld libbfd.c bfd_putl64 memory corruptionEPSS 0.6%CVE-2002-2439Integer overflow in the new[] operator in gcc before 4.8.0 allows attackers to have unspecified impacts.EPSS 0.5%CVE-2026-48829HIGHIn GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanyiEPSS 0.5%CVE-2025-69720HIGHThe infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.EPSS 0.4%CVE-2025-45582MEDIUMGNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victEPSS 0.4%CVE-2025-43921MEDIUMGNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE:EPSS 0.4%CVE-2024-56738MEDIUMGNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.EPSS 0.4%CVE-2026-56355LOWGNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.EPSS 0.4%CVE-2026-28372HIGHtelnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added EPSS 0.4%CVE-2025-1372MEDIUMGNU elfutils eu-readelf readelf.c print_string_section buffer overflowEPSS 0.3%CVE-2025-1365MEDIUMGNU elfutils eu-readelf readelf.c process_symtab buffer overflowEPSS 0.3%CVE-2026-9605MEDIUMGNU libredwg Dwgbmp Utility bits.c bit_read_RC heap-based overflowEPSS 0.3%CVE-2026-41992MEDIUMGlobal Buffer Overflow in GNU gzipEPSS 0.3%